CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability...Show more |
1Couchbase 1Couchbase Server Jun 17, 2026 May 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were ex...Show more |
1Ibm 1Qradar User Behavior Analytics Jun 17, 2026 May 14, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force ID: 196334. |
1Querysol 1Redirection For Contact Form 7 Jun 17, 2026 May 14, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker coul...Show more |
1Querysol 1Redirection For Contact Form 7 Jun 17, 2026 May 14, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site. |
1Querysol 1Redirection For Contact Form 7 Jun 17, 2026 May 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository. |
1Querysol 1Redirection For Contact Form 7 Jun 17, 2026 May 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function. |
Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream...Show more |
1Theforeman 1Smart Proxy Shell Hooks Jun 17, 2026 May 12, 2021 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenti...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreJun 17, 2026 May 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affect...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 May 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Container Manager Service Elevation of Privilege Vulnerability |
1Ibm 1Cloud Pak For Security Jun 17, 2026 May 10, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919...Show more |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreJun 17, 2026 May 10, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 May 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecti...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed. |
1Wpbakery Page Builder Clipboard Project 1Wpbakery Page Builder Clipboard Jun 17, 2026 May 6, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license op...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 30, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extens...Show more |
AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpo...Show more |
NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control unauthorized resources, which may lead to integrity and confidentiality loss or information disclosur...Show more |